SlideShare a Scribd company logo
Secure Android ApplicationsThe OWASP WayJack ManninoCEO/Chief “Breaker”ISSA DC- June 21, 2011https://www.nvisiumsecurity.comhttp://twitter.com/jack_manninohttp://www.linkedin.com/pub/jack-mannino/7/2b7/562©2011 nVisium Security Inc.
OverviewWho I am/ What we do
OWASP Mobile Security Project
Mobile World Meets Security World
Android Crash Course
Threat Modeling Android Apps
Risks and Controls
Where Do We Go From here?
Q&A, ResourcesWho I Am/ What We Do/ Where We AreWho I am
Jack Mannino
Company co-founder
Co-leader of the OWASP Mobile Security Project
Has a lot of phones…..
What we do:
Mobile Application Security
Web Application Security
Penetration Testing
Secure Development Training
Where we are:
Northern VirginiaOWASP Mobile Security Project
OWASP Mobile Security ProjectBegan in 2010
Current state of mobile application security: bad
We are aiming to make it: good
How do we plan to achieve this?OWASP Mobile Security Project
DisclaimerWe support OWASP by contributing expertise to the security community
OWASP does not support or endorse our business and services
Why am I mentioning this?
https://www.owasp.org/index.php/OWASP_brand_usage_rulesMobile World Meets Security World
Mobile World Meets Security WorldOnce upon a time, all phones could do was make phone calls….
And then, the world changed
Today’s mobile devices do things like
Make phone calls
Send SMS messages
Browse the web
VPN into corporate assets
Video conferencing
Track our location
Tap our phones to pay for things (soon)
Is anyone making money?
Do people use these things and their “apps”?Mobile World Meets Security World- Show Me The Money!!“Gartner Forecasts Mobile App Store Revenues Will Hit $15 Billion in 2011” (http://techcrunch.com/2011/01/26/mobile-app-store-15-billion-2011/)“Industry first: Smartphones pass PCs in sales” (http://tech.fortune.cnn.com/2011/02/07/idc-smartphone-shipment-numbers-passed-pc-in-q4-2010/)
Android Crash Course
And Now…Android!Debuted in 2008
Most popular mobile platform aroundPeople Use Android….Now What?Huge market share + attack monetization = target
Android Market is OPEN (in a bad way)

More Related Content

Secure Android Apps- nVisium Security